Cisco FMC flaws under active attack by ransomware crews

Cisco FMC flaws under active attack by ransomware crews

Three threat clusters, one running Qilin ransomware, are exploiting two patched Cisco FMC flaws; U.S. agencies must patch by September 12, 2026.

Cisco FMC flaws are under active attack, and the company that makes the product says three separate threat groups have been exploiting two recently patched vulnerabilities in it. Cisco FMC, short for Secure Firewall Management Center, is the central console that IT teams use to set up, monitor and control the Cisco firewalls protecting a network. Because it stores firewall rules, administrator logins and a live picture of the network it guards, it is an attractive place for an intruder to stay. Cisco's own threat research team, Cisco Talos, says it identified three clusters of activity on FMC instances that had already been compromised, and that these clusters are associated with criminal ransomware operations and with state-sponsored actors.

The first of the two flaws is CVE-2026-20079, rated 10.0 on the CVSS scale, which is the maximum severity score. It is an authentication bypass in the web interface of FMC software. In plain terms, the login check can be skipped altogether: an attacker who can reach that interface over a network needs no account and no password, and can run script files on the affected device to obtain root access to the operating system underneath. Root is the highest level of control on a machine. A CVE is the standard reference number given to a publicly catalogued software flaw so that people can look it up, and CVSS is a widely used scoring system for how serious a flaw is. The second flaw, CVE-2026-20316, is rated 5.3 and allows an unauthenticated, remote attacker to log in to an affected device using a low-privilege account and reach sensitive data held on vulnerable systems. Cisco notes that it can also be paired with other Cisco Secure FMC vulnerabilities to raise an attacker's privileges further.

Cisco Talos described three clusters of post-compromise activity, each tracked under its own label. The first, UAT-12197, exploited CVE-2026-20079 to deploy web shells, which are small scripts an intruder leaves on a server in order to return later and run commands through it, written in the Java Server Pages (JSP) format, together with a command execution tool packaged as a Java Archive (JAR). According to the research team, the goal was to query internal databases and obtain user authentication data and credentials. The second cluster, UAT-11823, exploited both flaws to deliver a reverse shell built on Netcat, a long-established networking tool that can open a command channel from the victim's machine back to the attacker, along with two bash scripts designed to harvest the configurations of the managed devices, and a variant of Cyclops Blink, a modular implant for Linux systems that Cisco says was previously attributed to Sandworm, a group it links to Russian state-sponsored activity.

The third cluster is the ransomware operation. UAT-11988 used CVE-2026-20316 for its initial access, then deliberately lived off the land: rather than bringing in purpose-built malware, it used legitimate tooling already built into FMC, so that its activity blended in with ordinary administration. Talos says this group carried out extensive reconnaissance of the victim's environment, dropped tunnelling tools to keep its network access open, collected credentials, built a target list of endpoints to encrypt, terminated security tools, and then deployed Qilin ransomware on the systems it had selected. Ransomware is malicious software that locks up files or systems and demands payment to give access back, and a tunnelling tool hides and carries an attacker's traffic through a network.

Cisco's guidance to customers is direct. The company said: "Customers are strongly advised to apply hotfixes for affected software versions already released by Cisco for CVE-2026-20079 and CVE-2026-20316." Cisco adds that it intends to ship a comprehensive hardening release next week covering various vulnerabilities it discovered internally. In the United States, the Cybersecurity and Infrastructure Security Agency (CISA) has added CVE-2026-20079 to its Known Exploited Vulnerabilities catalog, a public list of flaws confirmed to be used in real attacks. A listing there requires Federal Civilian Executive Branch agencies to apply the patches by September 12, 2026. The second vulnerability, CVE-2026-20316, was added to the same catalog in late July 2026.

What does this mean if you run a website or a business network? The pattern here is a familiar one and it is worth taking personally. The entry point is not a clever new trick but a management interface that is reachable over a network and still unpatched, and the damage is done afterwards, quietly, using the victim's own tools. That is why the two things that matter most are speed and exposure: getting the vendor's hotfixes installed on every affected system, and making sure that administration panels are not open to the whole internet in the first place. Because the FMC console manages firewalls, the credentials and configuration data it holds are exactly what an attacker needs to move deeper into a network, so a compromise there is rarely contained to one device. Anyone who is unsure whether their own firewalls or management software are affected should ask their IT provider directly, and ask for a specific answer about these two CVE identifiers rather than a general reassurance. Where organisations do not have in-house specialists to track patch releases and the exposure of management interfaces, AEU-I provides security-first IT, infrastructure and consulting, and its service page sets out the kind of ongoing hardening and support work this upkeep involves.

How to Protect Yourself

  1. If your company uses Cisco firewalls, ask whoever manages them to confirm the hotfixes for CVE-2026-20079 and CVE-2026-20316 are installed, and ask for that in writing.
  2. Ask your IT provider to keep administrative and management pages off the open internet so they can only be reached from inside your own network or through a secure private connection.
  3. Turn on two-step verification for your important accounts, so that a stolen password alone is not enough for someone to get in.
  4. Keep a recent backup of your website and important files somewhere that is not connected to your main systems, so ransomware cannot reach the copy as well.
  5. Check your admin accounts for logins you do not recognise and report anything odd to your IT team straight away.

Vulnerabilities & Fixes

  • CVE-2026-20079 An authentication bypass in the web interface of Cisco FMC software, rated 10.0 on the CVSS scale, for which Cisco has released hotfixes and which CISA has added to its Known Exploited Vulnerabilities catalog. View the fix & details →
  • CVE-2026-20316 A flaw rated 5.3 that lets an unauthenticated, remote attacker log in with a low-privilege account to reach sensitive data, and which can be combined with other FMC vulnerabilities; Cisco has released hotfixes and it was added to the KEV catalog in late July 2026. View the fix & details →

Terms Explained

  • FMC Short for Firewall Management Center, the central software console a company uses to set up and watch over its Cisco firewalls.
  • authentication bypass A weakness that lets someone into a system without logging in, by skipping the check that would normally ask for a password.
  • CVE A standard reference number given to a publicly known software security flaw so people can look it up.
  • CVSS score A number from 0 to 10 that rates how severe a software flaw is, where 10 is the most serious.
  • web shell A small script an intruder leaves on a server so they can come back later and run commands through it.
  • living off the land When an attacker uses tools already installed on the victim's own system instead of adding new software, so the intrusion is harder to spot.
  • ransomware Malicious software that locks up files or systems and demands payment to give access back.
  • KEV catalog The Known Exploited Vulnerabilities catalog, a public list kept by the U.S. cybersecurity agency of flaws that attackers are known to be using.

Related AEU services

  • AEU-I IT and security consulting